Authentication
Session-cookie auth for every API call, and what to do when a request returns 401.
Last updated · September 2026
On this page
All APIs authenticate with the same signed session cookie the web app uses, or with a CLI Bearer token. Sign in through the normal flow, keep the cookie, and send it with each request. Terminal callers mint a token once via POST /api/cli/token — see Bolt CLI.
Making an authenticated request
cURL with a session cookiebash
curl https://your-domain.com/api/auth/me \ -H 'Cookie: bolt_session=<session-token>'
cURL with a CLI tokenbash
curl https://your-domain.com/api/dashboard/stats \ -H 'Authorization: Bearer <cli-token>'
JavaScript (same origin)javascript
const res = await fetch("/api/auth/me", { credentials: "include" });
const me = await res.json();
// { authenticated: true, email, role, isAdmin, products, tokenBalance }When auth fails
| Status | Meaning | What to do |
|---|---|---|
| 401 | Missing, expired, or revoked session. | Sign in again and retry with a fresh cookie. |
| 403 | Signed in, but lacking permission (e.g. non-admin on an admin route, or non-member on an org route). | Check roles and organization membership. |
Keep tokens server-side
The session cookie is HttpOnly in the browser. Never copy session tokens into client-side logs, URLs, or error reports.
Was this page helpful?

